Reverse Engineering796 CVE-2026-58532: An Integer Overflow in Windows tcpip.sys
A user-controlled 64-bit record count multiplied by the 0x228 record size wraps to zero in the Windows tcpip.sys WFP ALE deserialiser, defeating…
Reverse Engineering796 A user-controlled 64-bit record count multiplied by the 0x228 record size wraps to zero in the Windows tcpip.sys WFP ALE deserialiser, defeating…
Privilege Escalation631 Cisco Talos disclosed CVE-2026-58613, a kernel use-after-free in cldflt.sys — the Windows Cloud Files Mini Filter Driver behind OneDrive Files On-Demand. An…
Exploit Development1.3k CVE-2026-58635 is a CWE-77 command injection in the Windows Narrator Braille (BRLTTY/BrlAPI) component: a standard user writes globally-writable parameter 29 with an…
AI Security Research775 Anthropic's Frontier Red Team showed Claude Opus 4.6 building a working browser exploit for CVE-2026-2796, a type-confusion bug in Firefox's SpiderMonkey WebAssembly…
Exploit Development1k Nightmare-Eclipse's LegacyHive is an unpatched Windows privilege-escalation flaw: a standard user coerces the SYSTEM-level User Profile Service into loading another user's registry…
Hardware522 Runic Labs dissects a QNAP QTS disclosure cycle — four bugs across three plugins (Notes Station 3, QmailAgent, QVPN) — and shows…
Full technical writeup of two critical unauthenticated RCEs in Unitree Go2 robots (V1.1.7-V1.1.11): CVE-2026-27509 DDS-based RCE and CVE-2026-27510 mobile database tampering, with…
Security Patches449 Dustin Childs reviews the July 2026 security patch cycle, covering 88 Adobe CVEs and a record-breaking 621 Microsoft vulnerabilities, including critical RCEs…
buffer overflow569 A two-bug nginx 1.30.0 chain: CVE-2026-42945 (Rift) heap overflow + CVE-2026-9256 (PoolSlip) heap over-read combine into an ASLR-independent remote system() call at…
buffer overflow556 CVE-2026-47291 is a critical unauthenticated RCE vulnerability in Windows HTTP.sys caused by a 16-bit integer overflow in the buffer reference array growth…
Exploit Development334 CVE-2026-34007 and CVE-2026-34008 expose a systemic pattern in QNAP QTS: header injection into shell_exec, hand-rolled SQL escaping, and unremapped container namespaces that…
Linux491 Pack2TheRoot (CVE-2026-41651) is a high-severity local privilege escalation flaw in PackageKit that lets any unprivileged user win a race condition during InstallFiles…